Audit a public website
The audit command uses the web scanner DNS, SSRF, timeout and response-size controls. Dry-run explains the planned requests without sending them.
The official CLI observes public resources and returns versioned JSON. It uses no credentials, writes no files, changes no websites and does not replace MCP.
Open CLI documentationThe audit command uses the web scanner DNS, SSRF, timeout and response-size controls. Dry-run explains the planned requests without sending them.
Registry get retrieves only published profiles and validates their contract. Drafts, dossiers and private observations remain out of scope.
OKF verify checks the manifest, routes, media types and SHA-256 values in memory. Each execution produces a stable response and predictable exit code.